Skip to content

Self-Host AgentZ

A self-hosted install runs on Kubernetes 1.34 or later with Cilium. The quick start puts everything on one server with K3s. The install order and the first commands are below. The full commands live in the repository guide.

Warning

Do not run make deploy to install AgentZ. It is a developer target that installs only the manager. Follow the guide below.

Prerequisites

  • A Linux server with at least 4 GiB of memory, 2 vCPU and 50 GiB of disk
  • Root access to the server
  • A domain with two DNS records.
    • An A record for agentz.example.com that points to the server.
    • A CNAME for s3.agentz.example.com that points to agentz.example.com.
  • Public TCP ports 80 and 443

Run the First Commands

Run these as root. Each command installs one layer and the next layer needs it.

# 1. K3s, without its default network layer
curl -sfL https://get.k3s.io | INSTALL_K3S_EXEC='--flannel-backend=none --disable-network-policy' sh -

Install the Cilium command-line tool.

# 2a. Cilium command-line tool
CILIUM_CLI_VERSION=$(curl -s https://raw.githubusercontent.com/cilium/cilium-cli/main/stable.txt)
CLI_ARCH=amd64
if [ "$(uname -m)" = "aarch64" ]; then CLI_ARCH=arm64; fi
curl -L --fail --remote-name-all https://github.com/cilium/cilium-cli/releases/download/${CILIUM_CLI_VERSION}/cilium-linux-${CLI_ARCH}.tar.gz{,.sha256sum}
sha256sum --check cilium-linux-${CLI_ARCH}.tar.gz.sha256sum
sudo tar xzvfC cilium-linux-${CLI_ARCH}.tar.gz /usr/local/bin
rm cilium-linux-${CLI_ARCH}.tar.gz{,.sha256sum}

Then install Cilium and enable Hubble.

# 2b. Cilium, then wait until it reports ready
cilium install --version 1.19.5 \
  --set ipam.operator.clusterPoolIPv4PodCIDRList=10.42.0.0/16 \
  --set operator.replicas=1
cilium status --wait

# 3. Hubble
cilium hubble enable

# 4. cert-manager
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.21.2/cert-manager.yaml

cilium status --wait ends when Cilium reports ready. Hubble is the Cilium tool that records network events.

Follow the Install Order

Install the rest in this order. Use the commands and versions in the guide. The guide pins AGENTZ_VERSION=v0.27.1.

  1. KubeArmor
  2. External Secrets Operator
  3. Gateway API CRDs, then AgentGateway
  4. CloudNativePG and a single-node PostgreSQL cluster
  5. OpenBao, with Kubernetes authentication, policies and roles
  6. The host and email variables, and the selfsigned and letsencrypt ClusterIssuers
  7. RustFS for S3-compatible storage, with the buckets agentz and agentz-assets
  8. The agentz-system namespace and its agentz Secret
  9. The Helm values file agentz-values.yaml
  10. The AgentZ Helm chart from deploy/helm, then a wait for the agentz-tls certificate

The guide runs helm upgrade --install agentz /root/agentz/deploy/helm. Clone the AgentZ repository to /root/agentz before you run it.

The complete guide is at github.com/accuknox/agentZ/tree/main/docs/self-hosting-guide.

Register the First Admin

  1. Open https://agentz.example.com/signup. Use your own domain.
  2. Enter your Name, Email, Password and Confirm password. Use the email address that you set as ADMIN_EMAIL in the guide.
  3. Make the password at least 12 characters, with a lowercase letter, an uppercase letter, a number and a symbol.
  4. Select Sign up. AgentZ shows a page while it provisions your organization, then opens it.

You are the Superadmin of that organization, and you are signed in. The guide lets only the ADMIN_EMAIL address sign up with a password. To add GitHub or Google sign-in, follow the social-login.md guide in the same folder.

Next Step

Continue with Create a workspace. Skip its sign-in step.